{"id":4047,"date":"2026-09-24T10:00:21","date_gmt":"2026-09-24T09:00:21","guid":{"rendered":"https:\/\/www.whysecurity.it\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\/"},"modified":"2026-09-24T10:00:24","modified_gmt":"2026-09-24T09:00:24","slug":"reimagining-the-soc-for-the-agentic-era-in-microsoft-defender","status":"publish","type":"post","link":"https:\/\/www.whysecurity.it\/en\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\/","title":{"rendered":"Reimagining the SOC for the agentic era in Microsoft Defender"},"content":{"rendered":"<p>The landscape of cybersecurity is undergoing a fundamental shift. As cyberattackers increasingly leverage automated agent frameworks to execute attacks at unprecedented scale, traditional security operations centers (SOCs) are struggling to keep pace. The core issue lies in the separation of security operations from native protection systems, which creates friction and delays that AI-driven threats exploit.<\/p>\n<p>To counter this, we are introducing the Integrated Security Operations Center (ISOC) in Microsoft Defender. ISOC moves beyond the limitations of isolated tools by unifying SIEM (Security Information and Event Management) and threat protection into a single, cohesive foundation. By integrating signals, sensors, context, and actuators, ISOC enables humans and agents to work as a unified system.<\/p>\n<p>Key pillars of the ISOC model include:<\/p>\n<ul>\n<li><strong>Agentic Foundation:<\/strong> Built to allow agents to perceive, reason, and act across the entire environment without the overhead of disparate systems.<\/li>\n<li><strong>Integrated Protection Loop:<\/strong> By breaking down linear workflows, ISOC enables continuous detection and disruption. It uses rich telemetry to predict and adapt to attacks in real-time, strengthening pre-breach protection automatically.<\/li>\n<li><strong>Practitioner-Centric Design:<\/strong> ISOC eliminates the need for teams to manually stitch together signals. Instead, all capabilities\u2014from investigation and hunting to automated response\u2014are available by default, allowing security professionals to shift their focus from operating tools to defining strategic outcomes.<\/li>\n<\/ul>\n<p>By uniting people and agents, ISOC allows defenders to operate at machine speed. Agents provide the scale and continuous execution required for modern defense, while human practitioners provide the judgment, priority-setting, and oversight necessary to achieve superior security outcomes.<\/p>\n<p>The ISOC in Microsoft Defender is available in preview today. As the race between attackers and defenders intensifies, the future of the SOC will be defined not by the number of AI features, but by the ability to act as one integrated system.<\/p>","protected":false},"excerpt":{"rendered":"<p>The landscape of cybersecurity is undergoing a fundamental shift. As cyberattackers increasingly leverage automated agent frameworks to execute attacks at unprecedented scale, traditional security operations centers (SOCs) are struggling to keep pace. The core issue lies in the separation of security operations from native protection systems, which creates friction and delays that AI-driven threats exploit. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4048,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-4047","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Reimagining the SOC for the agentic era in Microsoft Defender - CyberSecurity Experts<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.whysecurity.it\/en\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Reimagining the SOC for the agentic era in Microsoft Defender - CyberSecurity Experts\" \/>\n<meta property=\"og:description\" content=\"The landscape of cybersecurity is undergoing a fundamental shift. As cyberattackers increasingly leverage automated agent frameworks to execute attacks at unprecedented scale, traditional security operations centers (SOCs) are struggling to keep pace. The core issue lies in the separation of security operations from native protection systems, which creates friction and delays that AI-driven threats exploit. [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.whysecurity.it\/en\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\/\" \/>\n<meta property=\"og:site_name\" content=\"CyberSecurity Experts\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/whysec\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-24T09:00:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-24T09:00:24+00:00\" \/>\n<meta name=\"author\" content=\"whysecurity\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"whysecurity\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\\\/\"},\"author\":{\"name\":\"whysecurity\",\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/#\\\/schema\\\/person\\\/aa3b7e95e9fd51fd7f39d48911fdfe0a\"},\"headline\":\"Reimagining the SOC for the agentic era in Microsoft Defender\",\"datePublished\":\"2026-09-24T09:00:21+00:00\",\"dateModified\":\"2026-09-24T09:00:24+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\\\/\"},\"wordCount\":303,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.whysecurity.it\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/immagine-4.jpg\",\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.whysecurity.it\\\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\\\/\",\"url\":\"https:\\\/\\\/www.whysecurity.it\\\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\\\/\",\"name\":\"Reimagining the SOC for the agentic era in Microsoft Defender - CyberSecurity Experts\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.whysecurity.it\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/immagine-4.jpg\",\"datePublished\":\"2026-09-24T09:00:21+00:00\",\"dateModified\":\"2026-09-24T09:00:24+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.whysecurity.it\\\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.whysecurity.it\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/immagine-4.jpg\",\"contentUrl\":\"https:\\\/\\\/www.whysecurity.it\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/immagine-4.jpg\",\"width\":940,\"height\":627},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.whysecurity.it\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Reimagining the SOC for the agentic era in Microsoft Defender\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/#website\",\"url\":\"https:\\\/\\\/www.whysecurity.it\\\/\",\"name\":\"WhySecurity\",\"description\":\"Cyber Security Network Services\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.whysecurity.it\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/#organization\",\"name\":\"WhySecurity\",\"url\":\"https:\\\/\\\/www.whysecurity.it\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/tempnewweb.whysecurity.it\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/logo_white.png\",\"contentUrl\":\"https:\\\/\\\/tempnewweb.whysecurity.it\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/logo_white.png\",\"width\":500,\"height\":91,\"caption\":\"WhySecurity\"},\"image\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/whysec\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/#\\\/schema\\\/person\\\/aa3b7e95e9fd51fd7f39d48911fdfe0a\",\"name\":\"whysecurity\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ca59ad0cd8de5b2222178a2dfd751991a577b51363cd53356ed10b18f5c54a2c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ca59ad0cd8de5b2222178a2dfd751991a577b51363cd53356ed10b18f5c54a2c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ca59ad0cd8de5b2222178a2dfd751991a577b51363cd53356ed10b18f5c54a2c?s=96&d=mm&r=g\",\"caption\":\"whysecurity\"},\"sameAs\":[\"https:\\\/\\\/whysecurity.it\"],\"url\":\"https:\\\/\\\/www.whysecurity.it\\\/en\\\/author\\\/whysecurity\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Reimagining the SOC for the agentic era in Microsoft Defender - CyberSecurity Experts","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.whysecurity.it\/en\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\/","og_locale":"en_US","og_type":"article","og_title":"Reimagining the SOC for the agentic era in Microsoft Defender - CyberSecurity Experts","og_description":"The landscape of cybersecurity is undergoing a fundamental shift. As cyberattackers increasingly leverage automated agent frameworks to execute attacks at unprecedented scale, traditional security operations centers (SOCs) are struggling to keep pace. The core issue lies in the separation of security operations from native protection systems, which creates friction and delays that AI-driven threats exploit. [&hellip;]","og_url":"https:\/\/www.whysecurity.it\/en\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\/","og_site_name":"CyberSecurity Experts","article_publisher":"https:\/\/www.facebook.com\/whysec","article_published_time":"2026-09-24T09:00:21+00:00","article_modified_time":"2026-09-24T09:00:24+00:00","author":"whysecurity","twitter_card":"summary_large_image","twitter_misc":{"Written by":"whysecurity","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.whysecurity.it\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\/#article","isPartOf":{"@id":"https:\/\/www.whysecurity.it\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\/"},"author":{"name":"whysecurity","@id":"https:\/\/www.whysecurity.it\/#\/schema\/person\/aa3b7e95e9fd51fd7f39d48911fdfe0a"},"headline":"Reimagining the SOC for the agentic era in Microsoft Defender","datePublished":"2026-09-24T09:00:21+00:00","dateModified":"2026-09-24T09:00:24+00:00","mainEntityOfPage":{"@id":"https:\/\/www.whysecurity.it\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\/"},"wordCount":303,"commentCount":0,"publisher":{"@id":"https:\/\/www.whysecurity.it\/#organization"},"image":{"@id":"https:\/\/www.whysecurity.it\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\/#primaryimage"},"thumbnailUrl":"https:\/\/www.whysecurity.it\/wp-content\/uploads\/2026\/09\/immagine-4.jpg","articleSection":["Cybersecurity"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.whysecurity.it\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.whysecurity.it\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\/","url":"https:\/\/www.whysecurity.it\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\/","name":"Reimagining the SOC for the agentic era in Microsoft Defender - CyberSecurity Experts","isPartOf":{"@id":"https:\/\/www.whysecurity.it\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.whysecurity.it\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\/#primaryimage"},"image":{"@id":"https:\/\/www.whysecurity.it\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\/#primaryimage"},"thumbnailUrl":"https:\/\/www.whysecurity.it\/wp-content\/uploads\/2026\/09\/immagine-4.jpg","datePublished":"2026-09-24T09:00:21+00:00","dateModified":"2026-09-24T09:00:24+00:00","breadcrumb":{"@id":"https:\/\/www.whysecurity.it\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.whysecurity.it\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.whysecurity.it\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\/#primaryimage","url":"https:\/\/www.whysecurity.it\/wp-content\/uploads\/2026\/09\/immagine-4.jpg","contentUrl":"https:\/\/www.whysecurity.it\/wp-content\/uploads\/2026\/09\/immagine-4.jpg","width":940,"height":627},{"@type":"BreadcrumbList","@id":"https:\/\/www.whysecurity.it\/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.whysecurity.it\/"},{"@type":"ListItem","position":2,"name":"Reimagining the SOC for the agentic era in Microsoft Defender"}]},{"@type":"WebSite","@id":"https:\/\/www.whysecurity.it\/#website","url":"https:\/\/www.whysecurity.it\/","name":"WhySecurity","description":"Cyber Security Network Services","publisher":{"@id":"https:\/\/www.whysecurity.it\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.whysecurity.it\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.whysecurity.it\/#organization","name":"WhySecurity","url":"https:\/\/www.whysecurity.it\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.whysecurity.it\/#\/schema\/logo\/image\/","url":"https:\/\/tempnewweb.whysecurity.it\/wp-content\/uploads\/2025\/10\/logo_white.png","contentUrl":"https:\/\/tempnewweb.whysecurity.it\/wp-content\/uploads\/2025\/10\/logo_white.png","width":500,"height":91,"caption":"WhySecurity"},"image":{"@id":"https:\/\/www.whysecurity.it\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/whysec"]},{"@type":"Person","@id":"https:\/\/www.whysecurity.it\/#\/schema\/person\/aa3b7e95e9fd51fd7f39d48911fdfe0a","name":"whysecurity","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/ca59ad0cd8de5b2222178a2dfd751991a577b51363cd53356ed10b18f5c54a2c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/ca59ad0cd8de5b2222178a2dfd751991a577b51363cd53356ed10b18f5c54a2c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ca59ad0cd8de5b2222178a2dfd751991a577b51363cd53356ed10b18f5c54a2c?s=96&d=mm&r=g","caption":"whysecurity"},"sameAs":["https:\/\/whysecurity.it"],"url":"https:\/\/www.whysecurity.it\/en\/author\/whysecurity\/"}]}},"_links":{"self":[{"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/posts\/4047","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/comments?post=4047"}],"version-history":[{"count":1,"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/posts\/4047\/revisions"}],"predecessor-version":[{"id":4049,"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/posts\/4047\/revisions\/4049"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/media\/4048"}],"wp:attachment":[{"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/media?parent=4047"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/categories?post=4047"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/tags?post=4047"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}